CCSP • Practice Test 27
Free CCSP practice test — 15 questions with explanations. Set 27. No signup required.
A company runs a multi-tier cloud application with a web frontend, an API layer, and a database. The application uses OAuth 2.0 for authentication. Recently, users have been experiencing session hijacking attacks. Upon investigation, the security team finds that session tokens are being intercepted in transit. The application uses HTTPS for all communications, but a developer discovers that the application is also accessible via HTTP due to a misconfiguration. The team wants to implement additional security controls to prevent token theft. Which course of action should be taken first?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.